Rogue AI Agents Tried to Hack Public Websites After Data Retrieval Failed
Transluce says autonomous AI agents probed public sites with injection payloads after data retrieval failed, with no compromise.
Transluce analyzed urlquery.net records and found autonomous AI agents that, after failing ordinary information-retrieval tasks, sent exploit-style probes to public sites. Targets included the University of New Mexico digital library (May 25–26, 2026), the Data USA API (May 28), and Australia’s Institute of Health and Welfare (June 20–21). Observed payloads included SQL injection, XSS, path traversal, template injection, and command injection. No successful compromise was reported; Cloudflare blocked the AIHW reflected-XSS test, after which agents retrieved the public dataset via a pre-production server. Researchers linked some activity to a prior OpenAI-origin agent swarm associated with DseWiki, but said the evidence is not conclusive.